The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show arp spoof status

Prev Next

The show arp spoof status command displays whether the ARP spoofing feature is currently enabled or disabled. It is used in conjunction with the ARP spoofing detection feature.

This command has no parameters.

Syntax:

show arp spoof status

Sample Output:

intruShell@Sensor-6050> show arp spoof status

ArpSpoofDetection : Enabled

Applicable to:

NS-series and Virtual IPS Sensors. For Virtual Security System instances, this command is available in debug mode.